Skip to content
This repository was archived by the owner on Jan 5, 2026. It is now read-only.

Use latest PyJWT#1951

Closed
sdawodu wants to merge 5 commits into
microsoft:mainfrom
cybsafe:pyjwt_upgrade
Closed

Use latest PyJWT#1951
sdawodu wants to merge 5 commits into
microsoft:mainfrom
cybsafe:pyjwt_upgrade

Conversation

@sdawodu
Copy link
Copy Markdown

@sdawodu sdawodu commented Jul 12, 2022

Fixes #1837

Description

Changes calls of jwt.decode to stop using dropped verify parameter

@sdawodu sdawodu requested a review from a team as a code owner July 12, 2022 13:40
@ghost
Copy link
Copy Markdown

ghost commented Jul 12, 2022

CLA assistant check
All CLA requirements met.

@sdawodu sdawodu marked this pull request as draft July 12, 2022 14:24
Copy link
Copy Markdown

@pedroserrudo pedroserrudo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good

@sdawodu sdawodu marked this pull request as ready for review July 13, 2022 10:04
@sdawodu sdawodu marked this pull request as draft July 13, 2022 13:21
@adamzr
Copy link
Copy Markdown

adamzr commented Sep 14, 2022

I need this to avoid cve-2022-29217 with the old version of pyJWT. Can we get this merged?

@alissonpelizaro
Copy link
Copy Markdown

I need this to avoid cve-2022-29217 with the old version of pyJWT. Can we get this merged?

Some tests failed with this merge, we need input from the Microsoft team on Azure DEVOPS for more details.
@axelsrz

@tracyboehrer
Copy link
Copy Markdown
Member

There are also conflicts that need to be resolved.

@sdawodu sdawodu marked this pull request as ready for review October 27, 2022 09:29
@tracyboehrer
Copy link
Copy Markdown
Member

@sdawodu Thanks. Apologies for the delay. We were required to turn off forked builds, which was keep me from merging this PR. I merged into another branch, and merged into main: #1973

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Request botframework-connector-> upgrade PyJWT package

5 participants